• FW: Re: Fwd: DNS Misconfiguration on- http://cyberia.net.sa/

    From Renters Inquiries@renters.inquiries@assurant.com to Bhangui, Sandeep - BLS CTR via bind-users on Thu Jun 11 22:23:34 2020
    From Newsgroup: comp.protocols.dns.bind

    --_000_BD50A26D2D1D426BA928C42A7A7FC0E81D6403EF0D23RENTERSINQU_ Content-Transfer-Encoding: quoted-printable
    Content-Type: text/plain; charset="Windows-1252"

    Dear Valued Customer,


    Thank you for your inquiry. Please let us know how we may assist you.


    If you have a Renter=92s policy, you can manage your policy online 24/7 at:=
    https://www.myassurantpolicy.com/

    You have access to a range of service options including:

    *
    View/update policy information
    *
    Manage your payments
    *
    Obtain proof of insurance
    *
    And much more



    Thank you for allowing us the opportunity to serve you.


    Sincerely,

    Insurance Services

    Assurant - Global Specialty Operations




    ------------------- Original Message -------------------
    From: Fred Morris
    Received: Fri Jun 05 2020 12:17:17 GMT-0400 (Eastern Daylight Time)
    To: Bhangui, Sandeep - BLS CTR via bind-users
    Subject: Re: Fwd: DNS Misconfiguration on- http://cyberia.net.sa/

    Hrmmm... I'm reminded of something else I've seen reported on recently...

    On Fri, 5 Jun 2020, Ejaz Ahmed wrote:
    localhost.cyberia.net.sa

    I don't know if you've been paying attention, but it's been reported that
    among others EBay has been port scanning visitor's devices [0]. Having localhost.ebay.com could be handy for them in terms of circumventing some
    rules on setting of cookies and the execution of scripts. Not saying
    that's what they're doing, heaven forbid.

    Any domain you visit could have entries in it which point to e.g.
    localhost or nonrouting addresses commonly used for gateways, things like
    that.

    This is not a DNS problem, it's a problem in what commonly used programs
    aid and abet in the name of "freedom of commerce" or something.

    --

    Fred Morris

    --

    [0] https://www.bleepingcomputer.com/news/security/ebay-port-scans-visitors-com= puters-for-remote-access-programs/

    _______________________________________________
    Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscri=
    be from this list

    ISC funds the development of this software with paid support subscriptions.=
    Contact us at https://www.isc.org/contact/ for more information.


    bind-users mailing list
    bind-users@lists.isc.org
    https://lists.isc.org/mailman/listinfo/bind-users

    **********************************************************************
    This e-mail message and all attachments transmitted with it may contain leg= ally privileged and/or confidential information intended solely for the use=
    of the addressee(s). If the reader of this message is not the intended rec= ipient, you are hereby notified that any reading, dissemination, distributi= on, copying, forwarding or other use of this message or its attachments is = strictly prohibited. If you have received this message in error, please not= ify the sender immediately and delete this message and all copies and backu=
    ps thereof. Thank you.

    --_000_BD50A26D2D1D426BA928C42A7A7FC0E81D6403EF0D23RENTERSINQU_ Content-Transfer-Encoding: quoted-printable
    Content-Type: text/html; charset="Windows-1252"

    <html>
    <head>
    <meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3DWindows-1= 252">
    </head>
    <body>
    <span style=3D"font-size: 12px; font-family: Tahoma, Verdana, Arial;">
    <table cellspacing=3D"2" cellpadding=3D"4" width=3D"100%" height=3D"100%"> <tbody>

    <td style=3D"background-color:#ffffff;font-family:verdana;font-size:10pt;"> <p>Dear Valued Customer,</p>
    <p><br>

    <p>Thank you for your inquiry. Please let us know how we may assist you. </=

    <p style=3D"margin:0in 0in 8pt;line-height:normal;"><font face=3D"Calibri">= <b><span style=3D"color:black;font-size:12pt;"><br>
    </span></b></font></p>
    <p style=3D"margin:0in 0in 8pt;line-height:normal;"><font face=3D"Calibri">= <b><span style=3D"color:black;font-size:12pt;">If you have a </span></b><b><span style=3D"color:rgb(197, 90, 17);font-size:12pt;">Renter= =92s</span></b><b><span style=3D"color:black;font-size:12pt;"> policy, you = can manage your policy online 24/7 at:
    </span></b></font><a href=3D"https://www.myassurantpolicy.com/"><span style= =3D"font-size:12pt;"><u><font color=3D"#0563c1" face=3D"Calibri">https://ww= w.myassurantpolicy.com/</font></u></span></a></p>
    <font face=3D"Times New Roman" size=3D"3"></font>
    <p style=3D"margin:0in 0in 8pt;line-height:normal;"><span style=3D"color:bl= ack;font-size:12pt;"><font face=3D"Calibri">You have access to a range of s= ervice options including:</font></span></p>
    <font face=3D"Times New Roman"></font>
    <ul class=3D"Articlesedit_article_div_secEdit RTE_list_style_position">

    <div style=3D"color:rgb(0, 0, 0);line-height:normal;font-style:normal;font-= weight:normal;margin-top:0in;margin-bottom:0pt;">
    <span style=3D"color:black;">View/update policy information</span></div> </li><li>
    <div style=3D"color:rgb(0, 0, 0);line-height:normal;font-family:&quot;Calib= ri&quot;,sans-serif;font-size:11pt;font-style:normal;font-weight:normal;mar= gin-top:0in;margin-bottom:0pt;">
    <span style=3D"color:black;font-size:12pt;">Manage your payments</span></di=

    </li><li>
    <div style=3D"color:rgb(0, 0, 0);line-height:normal;font-family:&quot;Calib= ri&quot;,sans-serif;font-size:11pt;font-style:normal;font-weight:normal;mar= gin-top:0in;margin-bottom:0pt;">
    <span style=3D"color:black;font-size:12pt;">Obtain proof of insurance</span= ></div>
    </li><li>
    <div style=3D"color:rgb(0, 0, 0);line-height:normal;font-family:&quot;Calib= ri&quot;,sans-serif;font-size:11pt;font-style:normal;font-weight:normal;mar= gin-top:0in;margin-bottom:8pt;">
    <span style=3D"color:black;font-size:12pt;">And much more</span></div>

    </li></ul>
    <p><br>

    <p>Thank you for allowing us the opportunity to serve you.</p>
    <p><br>

    <p>Sincerely,</p>
    <p>Insurance Services</p>
    <p>Assurant - Global Specialty Operations&nbsp; </p>
    </td>
    </tr>
    <tr height=3D"100%">
    <td><br>
    </td>
    </tr>
    </tbody>
    </table>
    </span><br>
    <div id=3D"signature" style=3D"font-size: 12px; font-family: Tahoma, Verdan=
    a, Arial;">
    </div>

    <font face=3D"Tahoma, Verdana, Arial" size=3D"2"><br>
    ------------------- Original Message -------------------<br>
    <b>From:</b> Fred Morris<br>
    <b>Received:</b> Fri Jun 05 2020 12:17:17 GMT-0400 (Eastern Daylight Time)<=

    <b>To:</b> Bhangui, Sandeep - BLS CTR via bind-users<br>
    <b>Subject:</b> Re: Fwd: DNS Misconfiguration on- http://cyberia.net.sa/</f= ont><br>

    <style>
    .EmailQuote {
    margin-left:1pt;
    padding-left:4pt;
    border-left:#800000 2px solid;
    }
    </style><font size=3D"2"><span style=3D"font-size:11pt;">
    <div class=3D"PlainText">Hrmmm... I'm reminded of something else I've seen = reported on recently...<br>

    On Fri, 5 Jun 2020, Ejaz Ahmed wrote:<br>
    &gt; localhost.cyberia.net.sa<br>

    I don't know if you've been paying attention, but it's been reported that <=

    among others EBay has been port scanning visitor's devices [0]. Having <br> localhost.ebay.com could be handy for them in terms of circumventing some <=

    rules on setting of cookies and the execution of scripts. Not saying <br> that's what they're doing, heaven forbid.<br>

    Any domain you visit could have entries in it which point to e.g. <br> localhost or nonrouting addresses commonly used for gateways, things like <=

    that.<br>

    This is not a DNS problem, it's a problem in what commonly used programs <b=

    aid and abet in the name of &quot;freedom of commerce&quot; or something.<b=


    --<br>

    Fred Morris<br>

    --<br>

    [0] <br>
    <a href=3D"https://www.bleepingcomputer.com/news/security/ebay-port-scans-v= isitors-computers-for-remote-access-programs/">https://www.bleepingcomputer= .com/news/security/ebay-port-scans-visitors-computers-for-remote-access-pro= grams/</a><br>

    _______________________________________________<br>
    Please visit <a href=3D"https://lists.isc.org/mailman/listinfo/bind-users">= https://lists.isc.org/mailman/listinfo/bind-users</a> to unsubscribe from t= his list<br>

    ISC funds the development of this software with paid support subscriptions.=
    Contact us at
    <a href=3D"https://www.isc.org/contact/">https://www.isc.org/contact/</a> f=
    or more information.<br>


    bind-users mailing list<br>
    bind-users@lists.isc.org<br>
    <a href=3D"https://lists.isc.org/mailman/listinfo/bind-users">https://lists= .isc.org/mailman/listinfo/bind-users</a><br>
    </div>
    </span></font>

    <HR>This e-mail message and all attachments transmitted with it may contain=
    legally privileged and/or confidential information intended solely for the=
    use of the addressee(s). If the reader of this message is not the intended=
    recipient, you are hereby notified that any reading, dissemination, distri= bution, copying, forwarding or other use of this message or its attachments=
    is strictly prohibited. If you have received this message in error, please=
    notify the sender immediately and delete this message and all copies and b= ackups thereof. Thank you.<BR>
    </body>
    </html>

    --_000_BD50A26D2D1D426BA928C42A7A7FC0E81D6403EF0D23RENTERSINQU_--
    --- Synchronet 3.18a-Linux NewsLink 1.113